Missing Authorization in RabbitMQ Server - #VU137247
Published: July 9, 2026
Vulnerability details
The vulnerability allows a remote user to create persistent cluster-wide resources without required configure permission.
The vulnerability exists due to missing authorization in the HTTP super-stream creation handler when handling HTTP API requests to create super-streams. A remote privileged user can send a crafted HTTP request to create persistent cluster-wide resources without required configure permission.
Only instances with the rabbitmq_stream_management plugin enabled are vulnerable.